Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

microweber — Vulnerabilities & Security Advisories 81

Browse all 81 CVE security advisories affecting microweber. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Microweber is an open-source drag-and-drop content management system designed for website creation and e-commerce. Its architecture, built on the Laravel framework, has historically exposed it to a significant volume of security flaws, with eighty-one Common Vulnerabilities and Exposures currently recorded. The most prevalent issues involve remote code execution, cross-site scripting, and SQL injection, often stemming from insufficient input validation and improper access controls. These vulnerabilities frequently allow attackers to escalate privileges or execute arbitrary commands on the underlying server. While no single catastrophic breach has defined its public history, the sheer number of disclosed defects indicates persistent maintenance challenges. Users must prioritize rigorous patching and configuration hardening to mitigate these risks, as the software’s modular nature can inadvertently expand the attack surface if third-party extensions are not similarly secured.

Top products by microweber: microweber/microweber microweber
CVE IDTitleCVSSSeverityPublished
CVE-2022-0688 Business Logic Errors in microweber/microweber — microweber/microweberCWE-840 2.7 -2022-02-20
CVE-2022-0690 Cross-site Scripting (XSS) - Reflected in microweber/microweber — microweber/microweberCWE-79 6.1 -2022-02-19
CVE-2022-0689 Use multiple time the one-time coupon in microweber/microweber — microweber/microweberCWE-840 4.3 -2022-02-19
CVE-2022-0678 Cross-site Scripting (XSS) - Reflected in microweber/microweber — microweber/microweberCWE-79 6.1 -2022-02-19
CVE-2022-0666 CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in microweber/microweber — microweber/microweberCWE-93 6.5 -2022-02-18
CVE-2022-0660 Generation of Error Message Containing Sensitive Information in microweber/microweber — microweber/microweberCWE-209 7.5 -2022-02-18
CVE-2022-0638 Cross-Site Request Forgery (CSRF) in microweber/microweber — microweber/microweberCWE-352 6.5 -2022-02-17
CVE-2022-0597 Open Redirect in microweber/microweber — microweber/microweberCWE-601 6.1 -2022-02-15
CVE-2022-0596 Improper Validation of Specified Quantity in Input in microweber/microweber — microweber/microweberCWE-1284 2.7 -2022-02-15
CVE-2022-0560 Open Redirect in microweber/microweber — microweber/microweberCWE-601 6.1 -2022-02-11
CVE-2022-0557 OS Command Injection in microweber/microweber — microweber/microweberCWE-78 7.2 -2022-02-11
CVE-2022-0558 Cross-site Scripting (XSS) - Stored in microweber/microweber — microweber/microweberCWE-79 5.4 -2022-02-10
CVE-2022-0504 Generation of Error Message Containing Sensitive Information in microweber/microweber — microweber/microweberCWE-209 7.5 -2022-02-08
CVE-2022-0505 Cross-Site Request Forgery (CSRF) in microweber/microweber — microweber/microweberCWE-352 6.5 -2022-02-08
CVE-2022-0506 Cross-site Scripting (XSS) - Stored in microweber/microweber — microweber/microweberCWE-79 5.4 -2022-02-08
CVE-2022-0378 Cross-site Scripting (XSS) - Reflected in microweber/microweber — microweber/microweberCWE-79 6.1 -2022-01-26
CVE-2022-0379 Cross-site Scripting (XSS) - Stored in microweber/microweber — microweber/microweberCWE-79 5.4 -2022-01-26
CVE-2022-0282 Cross-site Scripting in microweber/microweber — microweber/microweberCWE-79 4.3 Medium2022-01-20
CVE-2022-0281 Exposure of Sensitive Information to an Unauthorized Actor in microweber/microweber — microweber/microweberCWE-200 7.5 -2022-01-20
CVE-2022-0278 Cross-site Scripting (XSS) - Stored in microweber/microweber — microweber/microweberCWE-79 5.4 -2022-01-20
CVE-2022-0277 Incorrect Permission Assignment for Critical Resource in microweber/microweber — microweber/microweberCWE-732--2022-01-20

This page lists every published CVE security advisory associated with microweber. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.